IMPLEMENTED CONTROLS

Security built into the investment process

Account access, sensitive documents and financial records are protected through layered controls designed to reduce unauthorized access, detect manipulation and support recoverability.

01

Account security

Argon2id password hashes, secure sessions, TOTP two-factor authentication, recovery codes, login throttling and sensitive-action reauthentication.

02

Encrypted file storage

Sensitive records and documents are encrypted using XChaCha20-Poly1305 when available, with authenticated AES-256-GCM fallback.

03

Financial integrity

Atomic writes, file locks, transaction journals, append-only financial events and hash-chained audit ledgers make unauthorized changes detectable.

04

Access control

Role-based permissions separate compliance, portfolio management, finance, support, trading and audit responsibilities.

05

Backups and recovery

Encrypted backups include integrity manifests, safe restore workflow, pre-restore backup and post-restore verification.

06

Web security

CSRF protection, output escaping, path validation, Content Security Policy, HSTS, secure cookies and restrictive browser permissions.

!
Security is a process, not a guarantee.

Hosting configuration, secret management, access reviews, legal controls, account permissions and tested restore procedures must remain operational after deployment.

Risk noticeDigital assets and alternative investment strategies involve substantial risk, including possible total loss. Returns are never guaranteed and historical results do not predict future performance.